Testing and Analyzing XProtectDetection - Jamf Protect Evaluation Guide

Jamf Protect Evaluation Guide

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

Follow the steps below to test the XProtectDetection analytic.

Warning:

Only test this detection using a virtual machine snapshot.

Requirements

On your virtual machine, download Gimmick from Objective-See's macOS Malware Collection (https://github.com/objective-see/Malware/raw/main/Gimmick.zip). This file contains an executable which triggers an XProtect detection for Gimmick malware.

  1. Open and extract the downloaded zip file.
  2. When prompted, enter the following password: infect3d.
  3. Run the extracted executable by double-clicking it.
  4. Confirm that an XProtect pop-up window appeared that advises of malicious content.
  5. Choose Trash or Cancel.
    After completing the testing simulation, a new alert titled XProtectDetection appears in the Jamf Protect Cloud.
  6. Open and review the XProtectDetection alert. The most interesting data points when analyzing this Alert are:
    • Summary > XProtectSignatureName: The threat name assigned by Apple to the threat signature used to identify this malware.

    • Summary > TimeStamp: The time at which the detection and quarantine of the malware occurred.

    • Summary > OriginURL: The origin URL of the page where the user initiated the download (Not always available).

    • Summary > DataURL: The true URL from which the malware was downloaded.

    • Summary > AgentBundleIdentifier: The application which completed the download, in this case the Safari browser.

    • Summary > UserAction: The action taken by the user when the XProtect pop-up window was presented to them.

    In a real world scenario, investigation of this alert should begin with identifying the file path of the malicious program as well as where the file came from to help understand whether it was testing or legitimate malware.

  7. If a virtual machine snapshot was taken prior to completing this test scenario the easiest cleanup method is to revert to the snapshot. Otherwise, remove the downloaded file and the extracted contents from the virtual Mac.
    1. When double-clicking the test executable select "Move to Trash" in the XProtect pop-up window to delete it.
    2. Empty Trash to confirm that the test executable has been completely removed.